Certified CMMC Assessor
Location: Fully Remote
Eligibility: Candidate must be a US Citizen eligible to obtain a security clearance (active clearance preferred)
Job Description: We're hiring CCAs at multiple experience levels — from early-career assessors, to seasoned Lead CCAs who can conduct and lead assessments end-to-end. Salary is commensurate with experience and certification level.
Responsibilities:
- CMMC Assessment Execution: Conduct formal CMMC Level 2 assessments per Cyber-AB guidelines, including documentation reviews, interviews, and technical validations
- Assessment Documentation & Reporting: Collect and evaluate evidence, document findings and scores, and support reporting for internal review and official submission
- Client Communication: Serve as a trusted advisor to clients, clearly communicating assessment criteria, observations, and outcomes; provide feedback and insights on remediation where applicable
- Framework Expertise: Maintain deep knowledge of CMMC, NIST SP 800-171, and DoD cybersecurity requirements; support continuous improvement of assessment methodologies
- Professional Development: Maintain required CCA certifications and stay current with evolving cybersecurity standards and best practices
Required Qualifications:
- Must be a U.S. Citizen (all employees are subject to a security screening)
- Possess Tier 3 Suitability
- Must have an Active CCA or Lead CCA certification from the Cyber-AB
- Bachelor's degree in Cybersecurity, Information Technology, Engineering, or related field; or equivalent professional experience
- Strong understanding of NIST SP 800-171, CMMC framework, and DoD cybersecurity requirements
- Exceptional written and verbal communication skills with meticulous attention to detail
- Proven ability to work independently and collaboratively in a remote/hybrid environment
Experience Requirements (by level):
- Entry-Level CCA: Newly certified CCA with limited or no assessment experience
- 1-2 years of experience in cybersecurity, IT security, or related field
- Familiarity with cybersecurity frameworks and compliance standards
- Strong desire to learn assessment methodologies
- Mid-Level CCA: 20+ completed CMMC Level 2 assessments
- 2-4 years of experience conducting cybersecurity assessments or working in highly regulated environments
- Demonstrated expertise in NIST SP 800-171 and CMMC Level 2 requirements
- Experience with GRC tools and assessment documentation
- Lead CCA: 10+ assessments completed in a lead assessor role
- 4+ years of experience conducting formal cybersecurity assessments
- Proven track record leading assessment teams and managing client relationships
- Deep expertise across multiple frameworks (CMMC, NIST 800-171, ISO 27001, CIS Controls)
- Experience mentoring junior assessors